In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc.
[
{
"digest": {
"line_hashes": [
"77868270333029608526007377023723104342",
"197616294696713652245393448113651582737",
"269458979685331922072839064529115824301",
"215176171713393582881742058038719741646",
"315085053996922377014046409675575957011",
"262883685267438665287262714275062867303",
"156884935239857457729986971900351574092",
"262207262755734626492622585168230902345",
"110923245719106072015242546838362036685"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2018-17019-6fd2cebe",
"target": {
"file": "src/analyzer/protocol/irc/IRC.cc"
},
"source": "https://github.com/bro/bro/commit/c2b18849f8bb833253538f5dfedb4ed1dc176a30"
},
{
"digest": {
"length": 24683.0,
"function_hash": "129660041364571452923689316779621065090"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2018-17019-71a0b4e7",
"target": {
"file": "src/analyzer/protocol/irc/IRC.cc",
"function": "IRC_Analyzer::DeliverStream"
},
"source": "https://github.com/bro/bro/commit/c2b18849f8bb833253538f5dfedb4ed1dc176a30"
}
]